Technical Tip: Auto failover to secondary SSL VPN remote gateway not working in FortiClient
| Description | This article describes that if users are using FortiClient to connect with an SSL VPN configured on the FortiGate, then they have a primary and secondary remote gateway for fail-over in case the primary goes down. Now, in this setup, the control to start SSL negotiation is on the endpoint level (FortiClient). FortiGate will always respond from the gateway where it received SSL negotiation packets. |
| Scope | FortiClient. |
| Solution | This can be verified with a packet sniffer on FortiGate, which only receives traffic from the primary gateway. If the primary gateway goes down, it will not do automatic fail-over (For the free version of FortiClient, up to version 7.4.3 GA).
If the primary gateway goes down user needs to change the remote gateway manually (For the free version of FortiClient, up to version 7.4.3 GA).
Here are the workarounds to make this auto-fail-over for the SSL gateway possible:
Related document: |

